fix(auth): clear a stale/expired JWT on 401 and skip /users/me without a token (#42) - #200
Merged
presidojay1 merged 2 commits intoSep 26, 2026
Conversation
…tellarTickets#42) refresh() swallowed every /users/me failure with setUser(null), leaving the dead token in localStorage so every request kept sending it. On a 401 (new isUnauthorized helper in api.ts) clear the token first; network/5xx errors still keep it since the session may be valid.
StellarTickets#42) With no token there is nothing to validate, so refresh() now sets the user to null without the network call that would fail on every page load. Adds unit tests: only a 401 ApiError clears the token; 403/5xx/network errors do not.
❌ Deploy Preview for stellartickets failed.
|
|
@miraclesonly Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
refresh()insrc/lib/auth-context.tsxcaught every/users/mefailure and only calledsetUser(null). An expired or invalid JWT stayed inlocalStorage, so:Authorizationheader;/users/mecall.Changes
isUnauthorized(err)helper insrc/lib/api.ts:err instanceof ApiError && err.status === 401.refresh()callsclearToken()beforesetUser(null).NetworkError, status 0) keep it, so a backend blip doesn't sign the user out./users/mewhen there's no token. With nothing stored,refresh()sets the user tonulland returns without a network call. After a 401 has cleared the token, later page loads no longer repeat the failing request.src/lib/api-unauthorized.test.tschecks thatisUnauthorizedis true only for a 401ApiError, and false for 403, 500,NetworkErrorand plain errors.Commits
fix(auth): clear an expired/invalid JWT when /users/me returns 401 (#42)fix(auth): skip /users/me when no token is stored; test isUnauthorized (#42)Testing
Not run locally. To check:
npm test.Manual check:
localStorage['stellartickets.token']./users/merequest is made.Closes A stale or expired JWT is never removed from localStorage #42
Closes Expired sessions mid-use produce generic errors instead of logging the user out #43
Closes
localStorageaccess is unguarded and throws in blocked-storage/private modes #44Closes
login/registersucceed then bounce the user back to /login when/users/mefails #45